Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access (XRX09-003)

This script is Copyright (C) 2009-2013 Tenable Network Security, Inc.


Synopsis :

The remote multi-function device may allow unauthorized access.

Description :

According to its model number and software version, the remote host
is a Xerox WorkCentre device that could allow a remote attacker to
obtain unauthorized access to device configuration settings, possibly
exposing customer passwords.

Note that successful exploitation requires that SSL is not enabled for
the web server component.

See also :

http://www.xerox.com/downloads/usa/en/c/cert_XRX09-003_v1.3.pdf

Solution :

Apply the P39 patch as described in the Xerox security bulletin
referenced above.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 3.7
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Misc.

Nessus Plugin ID: 40807 ()

Bugtraq ID: 36177

CVE ID:

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial